An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. They allow remote IMAP servers to execute arbitrary commands via backquote characters, related to the mailboxes command associated with an automatic subscription.
[
{
"signature_type": "Function",
"digest": {
"function_hash": "25232212404975938392095324741979721523",
"length": 411.0
},
"target": {
"file": "imap/util.c",
"function": "imap_quote_string"
},
"signature_version": "v1",
"id": "CVE-2018-14357-21eb7944",
"deprecated": false,
"source": "https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "54145826516367523844483083921749081584",
"length": 1020.0
},
"target": {
"file": "imap/auth_login.c",
"function": "imap_auth_login"
},
"signature_version": "v1",
"id": "CVE-2018-14357-3ef2ade0",
"deprecated": false,
"source": "https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"40059947202003753882794158162630602032",
"33957418988982031953252871012599315498",
"14440449832509296460349422180754625881",
"328550919031994469811580118784132661353"
]
},
"target": {
"file": "imap/imap_private.h"
},
"signature_version": "v1",
"id": "CVE-2018-14357-50f6d5c8",
"deprecated": false,
"source": "https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "228645823018358539514830665902340320393",
"length": 1124.0
},
"target": {
"file": "imap/command.c",
"function": "cmd_parse_lsub"
},
"signature_version": "v1",
"id": "CVE-2018-14357-59e01704",
"deprecated": false,
"source": "https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "291529779614175762299804966543294971833",
"length": 1785.0
},
"target": {
"file": "imap/imap.c",
"function": "compile_search"
},
"signature_version": "v1",
"id": "CVE-2018-14357-9d1cab05",
"deprecated": false,
"source": "https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"290371799708502961206057772632536943091",
"18535148220572482381713302160943144077",
"112636599605313640367218014315756889488",
"155916374119256125216399603904507973822",
"286118849534253534257468740577239685662",
"223538712502296627128770503380775501472",
"249381483255595934883473801724589076338",
"30161640952715552746956554296785670435",
"289232574174694656604675269615861344305",
"237931762224159757948265487617735571981",
"160280846770068004037930240257375366972",
"330590195154125417232703690332110355416",
"240245407675162988225333038990089718837",
"126289386742731416981764470008903900873",
"265881874339859241327523780800113630105",
"318222868274895948634329615183172928997",
"189972794556539960752497622871393179339",
"59123788372805168635155429699586443622",
"270760812293094337621602240599557051224",
"204593421235506536873346765773146028705",
"21128045233681405009357938533431397937",
"33551005496761524339892479546261424258"
]
},
"target": {
"file": "imap/imap.c"
},
"signature_version": "v1",
"id": "CVE-2018-14357-a4b01ba9",
"deprecated": false,
"source": "https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "307367527101721205064864789758691292796",
"length": 208.0
},
"target": {
"file": "imap/util.c",
"function": "imap_munge_mbox_name"
},
"signature_version": "v1",
"id": "CVE-2018-14357-aba3a888",
"deprecated": false,
"source": "https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"66137756997161504403941217310727372939",
"310724314558957576833016873785582727811",
"19095377894295592758775701765302495655",
"151220952131806283612168267188891647283",
"135727516109020326077663382957561960938",
"111392465137362549631186206197069015454",
"72503969521256924378459959459631535089",
"133567269710818315285880532153331164207",
"335229863770071323446310299064130419504",
"91241925715385398596810934857741489207"
]
},
"target": {
"file": "imap/util.c"
},
"signature_version": "v1",
"id": "CVE-2018-14357-da296675",
"deprecated": false,
"source": "https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"132748155327204630174065284245821983324",
"40563222551239612949093301883425487716",
"121955452387884587719052491384722837387",
"151693653993940274130361879860361198131"
]
},
"target": {
"file": "imap/command.c"
},
"signature_version": "v1",
"id": "CVE-2018-14357-e8be0a36",
"deprecated": false,
"source": "https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"30679469574901647276382938894779000438",
"32555205313492347667504547345303343458",
"153293687321224632157823591860082995634",
"102068395844681187141800602681383507130",
"330017860411233662183258026172732541333"
]
},
"target": {
"file": "imap/auth_login.c"
},
"signature_version": "v1",
"id": "CVE-2018-14357-faa9f54a",
"deprecated": false,
"source": "https://github.com/neomutt/neomutt/commit/e52393740334443ae0206cab2d7caef381646725"
}
]
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"218563899158595001308791628437925633403",
"227032016281452034997778241664359416981",
"121955452387884587719052491384722837387",
"506689728705518440064826266314589397"
]
},
"target": {
"file": "imap/command.c"
},
"signature_version": "v1",
"id": "CVE-2018-14357-0899ff95",
"deprecated": false,
"source": "https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"31952942522484068575409883696072157290",
"150718647487976241170236887315804442895",
"195246979766333573439280635801526022618",
"45908318597331465607108365531724022732"
]
},
"target": {
"file": "imap/imap_private.h"
},
"signature_version": "v1",
"id": "CVE-2018-14357-10a917db",
"deprecated": false,
"source": "https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"38275816934835526550139553849663291777",
"84668977590220873947543140367782392958",
"272858250823638590734560816738299859458",
"197331919126694590783117091847939465809",
"51941361508920648674779441686070670670",
"194784290279722335795310118604540377499",
"212420238482727122243216053129668158301",
"1736061709541927672894172239778923985",
"97656863909256314289154183120921480207"
]
},
"target": {
"file": "imap/imap.c"
},
"signature_version": "v1",
"id": "CVE-2018-14357-62f6c109",
"deprecated": false,
"source": "https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "42665550993922102829047012000358714254",
"length": 1439.0
},
"target": {
"file": "imap/imap.c",
"function": "imap_subscribe"
},
"signature_version": "v1",
"id": "CVE-2018-14357-632ede0e",
"deprecated": false,
"source": "https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "246102907976701583778681406207369390654",
"length": 417.0
},
"target": {
"file": "imap/util.c",
"function": "imap_quote_string"
},
"signature_version": "v1",
"id": "CVE-2018-14357-a951c6d9",
"deprecated": false,
"source": "https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"229097236898046633024934805433464608349",
"83602381607473313393815366418147480894",
"19095377894295592758775701765302495655",
"176494269792467988790647947745744230920",
"203644126986609072164389678235740350197",
"133503302104114886261060629320855893432",
"82663813847307772799785084971472340363",
"302829093608743047112308803954531093411",
"155024479240875832356848830543203950212",
"22431226980439760116591360907198255704",
"82123232775065497543890611821024729842",
"55123122238136819455069850209539057260",
"319011740409708478183254388973645564560"
]
},
"target": {
"file": "imap/util.c"
},
"signature_version": "v1",
"id": "CVE-2018-14357-cc57081f",
"deprecated": false,
"source": "https://gitlab.com/muttmua/mutt@185152818541f5cdc059cbff3f3e8b654fc27c1d"
}
]